CVE Database /
CVE-2025-13773
CVE · Critical
CVE-2025-13773 — Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13773
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.8
|
< 5.9.0
|
5.9.0 |
2025-12-23 |
—
|
CVE-2025-13773
The Print Invoice & Delivery Notes for WooCommerce plugin has a security flaw that allows unauthorized access to execute arbitrary commands on the server. This vulnerability exists due to an oversight in capability checks within the update function, combined with PHP being enabled in Dompdf and a missing escape character in the template file. As a result, attackers can exploit this weakness without needing authentication credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings